Per OWASP, the Likelihood estimate and the Impact estimate are put together to calculate an overall Severity for this risk.
This is done by figuring out whether the Likelihood is Low, Medium, or High and then do the same for impact.
- OWASP proposes a 3x3 Severity Matrix which combines the three Likelihood levels with the three Impact levels
- Severity Matrix (Likelihood-Impact = Severity):
Likelhood | Impact | Severity |
---|---|---|
Low | Low | Note |
Low | Med | Low |
Low | High | Medium |
Med | Low | Low |
Med | Med | Med |
Med | High | High |
High | Low | Med |
High | Med | High |
High | High | Critical |
- Trail of Bits uses:
- Informational: The issue does not pose an immediate risk, but is relevant to security best practices or Defence in Depth
- Undetermined: The extent of the risk was not determined during this engagement
- Low: The risk is relatively small or is not a risk the customer has indicated is important
- Medium: Individual user’s information is at risk, exploitation would be bad for client’s reputation, moderate financial impact, possible legal implications for client
- High: Large numbers of users, very bad for client’s reputation, or serious legal or financial implications
- ConsenSys uses:
- Minor: issues are subjective in nature. They are typically suggestions around best practices or readability. Code maintainers should use their own judgment as to whether to address such issues.
- Medium: issues are objective in nature but are not security vulnerabilities. These should be addressed unless there is a clear reason not to.
- Major: issues are security vulnerabilities that may not be directly exploitable or may require certain conditions in order to be exploited. All major issues should be addressed.
- Critical: issues are directly exploitable security vulnerabilities that need to be fixed.
Likelhood | Impact | Severity |
---|---|---|
Low | Low | Note |
Low | Med | Low |
Low | High | Medium |
Med | Low | Low |
Med | Med | Med |
Med | High | High |
High | Low | Med |
High | Med | High |
High | High | Critical |